Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.82% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 1/7/2021 | 17/6/2026 | Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter. | |
| Modificada | Media (6.5) | 0.68% | — | F-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Endpoint ProtectionF-secure Linux Security | 21/6/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… | |
| Modificada | Media (5.4) | 0.87% | — | Salesagility Suitecrm | 30/4/2021 | 17/6/2026 | XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field | |
| Modificada | Alta (7.5) | 93% | — | Oracle Sales Offline | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful… | |
| Modificada | Alta (7.5) | 15% | — | Oracle Sales Offline | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful… | |
| Modificada | Crítica (9.8) | 1.2% | — | Salesforce Mule | 26/3/2021 | 17/6/2026 | MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021. | |
| Modificada | Crítica (9.8) | 1.0% | — | Salesforce Mule | 26/3/2021 | 17/6/2026 | MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021. | |
| Modificada | Crítica (9.8) | 2.0% | — | Salesforce Mule | 26/3/2021 | 17/6/2026 | MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions affected: Mule 4.1.x and 4.2.x runtime released before February 2, 2021. | |
| Modificada | Crítica (9.8) | 1.3% | — | Point OF Sales IN Php/pdo Project Point OF Sales IN Php/pdo | 2/12/2020 | 17/6/2026 | SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php. | |
| Modificada | Media (6.1) | 0.71% | — | Salesagility Suitecrm | 18/11/2020 | 17/6/2026 | SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document. | |
| Modificada | Media (5.4) | 0.64% | — | Salesagility Suitecrm | 18/11/2020 | 17/6/2026 | SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML. | |
| Modificada | Alta (7.8) | 0.79% | — | Salesagility Suitecrm | 18/11/2020 | 17/6/2026 | SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation. | |
| Modificada | Crítica (9.8) | 2.1% | — | Simple Grocery Store Sales AND Inventory Sales Project Simple Grocery Store Sales AND Inventory System | 17/11/2020 | 17/6/2026 | An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php. | |
| Modificada | Alta (8.8) | 63% | 💥 Exploit | Salesagility Suitecrm | 6/11/2020 | 17/6/2026 | SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root. | |
| Modificada | Media (6.1) | 1.9% | — | Adobe Marketo Sales Insight | 20/10/2020 | 17/6/2026 | Marketo Sales Insight plugin version 1.4355 (and earlier) is affected by a blind stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Modificada | Media (5.4) | 0.85% | — | Ni-consul Sales Force Assistant | 28/4/2020 | 17/6/2026 | Cross-site scripting vulnerability in Sales Force Assistant version 11.2.48 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.1) | 5.8% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+14 | 7/4/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). | |
| Analizada | Alta (8.1) | 3.7% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+17 | 7/4/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). | |
| Analizada | Alta (8.8) | 6.3% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+28 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). | |
| Analizada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+21 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 26/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 26/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). | |
| Modificada | Media (5.3) | 0.87% | — | Salesagility Suitecrm | 20/3/2020 | 17/6/2026 | SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism. | |
| Modificada | Alta (8.8) | 8.0% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 18/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). |